Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
  • DeFi
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • Gaming
  • Legal
    • Taxes & Regulation
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Converter
What's Hot

Senate Passes Landmark Stablecoin Bill in Major Boon for Crypto Industry

June 20, 2025

Best New Crypto to Buy as Arizona Reconsiders Bitcoin Reserve Bill

June 20, 2025

Arizona revives bid for seized crypto reserve fund through House Bill 2324

June 20, 2025
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) Instagram
Buy Crypto NewsBuy Crypto News
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. View All

    Crypto Market Faces Short-term Bearish Sentiment After Fed Left Interest Rate Unchanged Akin to BoJ

    June 20, 2025

    Bitcoin Reclaiming This Critical Resistance Level Would Be a Big Signal for the Next Leg Up, Says Analyst Michaël van de Poppe

    June 20, 2025

    NEAR Protocol Surges 5% as Buyers Dominate Amid Middle East Tensions

    June 20, 2025

    ‘Ancient’ Bitcoin Supply Now Outpacing Newly Mined BTC: Fidelity Report

    June 19, 2025

    Analyst Predicts 20% Ethereum Price Crash Below $2,000, Here’s Why

    June 20, 2025

    Ethereum whale stakes $18M at a loss, but retail is dumping! – Who’s right?

    June 20, 2025

    Here’s Why ETH is Poised for a Megarally

    June 20, 2025

    Is Ethereum Price Set To Repeat History As 2017 Playbook Returns? Why This Time Could Be Bigger

    June 19, 2025

    Best New Crypto to Buy as Arizona Reconsiders Bitcoin Reserve Bill

    June 20, 2025

    Could a nuclear war kill crypto? AI predicts Bitcoin’s fate in doomsday scenario

    June 20, 2025

    Is RXS the Best Low-Cap Bet for the 2025 Bull Market?

    June 20, 2025

    Solana Memecoin About To ‘Blast Through’ All-Time Highs, According to Veteran Crypto Trader

    June 19, 2025

    Pepe, BMT, CAKE: Crypto Activity Heats Up

    March 18, 2025

    SHIB Burns Over Half a Billion Tokens, Price Surges Over 7%

    March 17, 2025

    DOGE Sees Massive User Growth: Active Addresses Up 400%

    March 15, 2025

    Shiba Inu (SHIB) Price Analysis: Bullish Hints, Bearish Trend

    March 15, 2025

    Senate Passes Landmark Stablecoin Bill in Major Boon for Crypto Industry

    June 20, 2025

    Best New Crypto to Buy as Arizona Reconsiders Bitcoin Reserve Bill

    June 20, 2025

    Arizona revives bid for seized crypto reserve fund through House Bill 2324

    June 20, 2025

    Jupiter halts governance voting to tackle burnout and refocus on innovation

    June 20, 2025
  • DeFi

    Jupiter halts governance voting to tackle burnout and refocus on innovation

    June 20, 2025

    AERO price breaks key resistance as futures open interest hits ATH

    June 20, 2025

    Raydium price forecast after the Upbit listing

    June 20, 2025

    PancakeSwap extends lead as monthly DEX volume tops $500B

    June 19, 2025

    Ethena Labs and Securitize enable 24/7 USDtb-BUIDL swaps

    June 19, 2025
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. View All

    Visa Taps Yellow Card for Stablecoin Payments Push Across 20 African Nations

    June 20, 2025

    JZXN Raises Capital via Convertible Notes to Buy Bitcoin

    June 20, 2025

    Russian Power Firm Launches Bitcoin Mining Mutual Investment Fund

    June 20, 2025

    Blockticity Launches L1 on Avalanche to Authenticate $1.2B+

    June 20, 2025

    North Korean Hackers Deploy Python-Based Trojan Targeting Crypto

    June 20, 2025

    Israeli Hacktivists Steal and Burn $90m+ from Iranian Crypo Biz

    June 19, 2025

    ZachXBT warns suspected ZKasino fraudster may be linked to new crypto venture WhiteRock

    June 17, 2025

    Threat Actors Target Victims with HijackLoader and DeerStealer

    June 17, 2025

    Senate Passes Landmark Stablecoin Bill in Major Boon for Crypto Industry

    June 20, 2025

    Best New Crypto to Buy as Arizona Reconsiders Bitcoin Reserve Bill

    June 20, 2025

    Arizona revives bid for seized crypto reserve fund through House Bill 2324

    June 20, 2025

    Jupiter halts governance voting to tackle burnout and refocus on innovation

    June 20, 2025
  • Web 3
    1. Web3 News
    2. Gaming
    3. View All

    Doodles NFT Sticker Launch on Telegram Sells Out in 24 Hours

    June 20, 2025

    ZTE showcases full-stack innovations at MWC Shanghai 2025, co-creating an era of AI for all

    June 20, 2025

    Location-Based Gaming NFTs: How GPS and Blockchain Are Changing the Way We Play

    June 20, 2025

    ReggaeEDM Takes The Stage | Web3Wire

    June 19, 2025

    A16z-backed Spekter Games founder shares Telegram gaming ethos

    June 20, 2025

    Crypto Casinos Made Over $80 Billion in 2024

    June 20, 2025

    Avalanche Game ‘Forgotten Playland’ Implements NFTs in Biggest Update Yet

    June 20, 2025

    How Mobile Apps Are Quietly Adopting Web3 Tech

    June 20, 2025

    Senate Passes Landmark Stablecoin Bill in Major Boon for Crypto Industry

    June 20, 2025

    Best New Crypto to Buy as Arizona Reconsiders Bitcoin Reserve Bill

    June 20, 2025

    Arizona revives bid for seized crypto reserve fund through House Bill 2324

    June 20, 2025

    Jupiter halts governance voting to tackle burnout and refocus on innovation

    June 20, 2025
  • Legal
    1. Taxes & Regulation
    2. Adoption
    3. View All

    Senate Passes Landmark Stablecoin Bill in Major Boon for Crypto Industry

    June 20, 2025

    Elizabeth Warren criticizes GENIUS Act over stablecoin concerns ahead of final vote

    June 20, 2025

    Ripple Says Negotiated Settlement Levels the Playing Field

    June 20, 2025

    Coinbase push for crypto-friendly UK gains momentum

    June 20, 2025

    Arizona revives bid for seized crypto reserve fund through House Bill 2324

    June 20, 2025

    X transforms into a finance hub but sidesteps crypto—for now

    June 20, 2025

    Ford explores decentralized legal data storage on Cardano blockchain

    June 19, 2025

    Two public firms announce plans to adopt HYPE as primary reserve asset for treasury

    June 19, 2025

    Senate Passes Landmark Stablecoin Bill in Major Boon for Crypto Industry

    June 20, 2025

    Best New Crypto to Buy as Arizona Reconsiders Bitcoin Reserve Bill

    June 20, 2025

    Arizona revives bid for seized crypto reserve fund through House Bill 2324

    June 20, 2025

    Jupiter halts governance voting to tackle burnout and refocus on innovation

    June 20, 2025
  • Analysis

    Story (IP) Price Plunges While Trading Volume Spikes Over 200%-What’s Going On?

    June 20, 2025

    Dogecoin Price Prediction: $0.10 Incoming or $1.25 Moonshot?

    June 19, 2025

    Institutional Investors Dump $50,780,000,000 in Stocks in Just One Month Amid US Bond Rating Downgrade and Trump Trade War: S&P Global

    June 19, 2025

    Why Is Cardano (ADA) Price Dropping Today? Here’s What You Need to Know!

    June 19, 2025

    Goldman Sachs Flips Bullish on Ten Stocks – Bank Says These Companies Could Be China’s ‘Magnificent 7’

    June 19, 2025
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What Are Internet Capital Markets? Why Companies Are Launching Meme Coins

    June 16, 2025

    What is a Corporate Bitcoin Treasury? The Strategy Behind Companies Holding Crypto

    May 27, 2025

    What Are Tokenized Real-World Assets? Putting Physical Value On-Chain With RWAs

    May 19, 2025

    Users Taunt Grok After xAI Says Modifications Were Made to Spit out ‘White Genocide’ Claim

    May 16, 2025

    Iran-based crypto exchange hacked for $48M amid cyberattack claims by Israel-linked group

    June 20, 2025

    Iran’s Nobitex loses $100 million to symbolic cyberattack

    June 20, 2025

    Coinbase launches stablecoin payment stack with USDC checkout targeting commerce giants

    June 19, 2025

    Circle’s USDC and BlackRock’s BUIDL spearhead collateral innovation in derivatives markets

    June 19, 2025

    Senate Passes Landmark Stablecoin Bill in Major Boon for Crypto Industry

    June 20, 2025

    Best New Crypto to Buy as Arizona Reconsiders Bitcoin Reserve Bill

    June 20, 2025

    Arizona revives bid for seized crypto reserve fund through House Bill 2324

    June 20, 2025

    Jupiter halts governance voting to tackle burnout and refocus on innovation

    June 20, 2025
  • Tools
    • Market Overview
    • Converter
Buy Crypto NewsBuy Crypto News
Home»Security and Privacy»XRP Ledger developer kit compromised with backdoor to steal wallet private keys
XRP Ledger developer kit compromised with backdoor to steal wallet private keys
Security and Privacy

XRP Ledger developer kit compromised with backdoor to steal wallet private keys

April 23, 2025No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Aikido Security recently uncovered a critical vulnerability in the XRP Ledger’s official JavaScript SDK, raising concerns about compromised versions of the XRPL Node Package Manager (NPM) package that were published to the registry starting April 21.

The affected versions, specifically v4.2.1 through v4.2.4 and v2.14.2, were found to contain a backdoor that could potentially exfiltrate private keys, posing a significant threat to crypto wallets relying on the software.

NPM packages serve as reusable modules for JavaScript and Node.js projects, simplifying the installation, updates, and removal processes. Aikido Security’s automated threat monitoring platform detected the anomaly when NPM user “mukulljangid” released five new versions of the XRPL package that did not align with any tagged releases on the official GitHub repository, triggering suspicions of a supply chain compromise.

Further analysis revealed that the compromised packages included a function called checkValidityOfSeed, which made external calls to the unverified domain 0x9c[.]xyz. This function, triggered during the wallet class instantiation, surreptitiously transmitted private keys during wallet creation.

Initially, the malicious code was embedded in the built JavaScript files of early versions (v4.2.1 and v4.2.2). Subsequent iterations (v4.2.3 and v4.2.4) introduced the backdoor into the TypeScript source files, which were then compiled into production code. The attacker’s tactics evolved from manual JavaScript manipulation to more sophisticated integration into the SDK’s build process.

This targeted attack against the crypto development infrastructure impacted hundreds of thousands of applications and websites utilizing the compromised XRPL package. The compromised versions also removed development tools and scripts from the package.json file, indicating deliberate tampering.

In response to the security vulnerability, the XRP Ledger Foundation promptly acknowledged the issue and initiated efforts to address the issue. The Foundation removed the affected versions from the NPM registry following the disclosure. However, the extent to which users had integrated the compromised versions before the issue was identified remains uncertain.

See also  XRP network activity surges as Canada launches an XRP ETF

Mark Ibanez, CTO of XRP Ledger-based Gen3 Games, highlighted the importance of best practices to mitigate risks, such as committing the “lockfile” to version control, utilizing Performant NPM (PNPM) when feasible, and avoiding unintended version upgrades by refraining from using the caret (^) symbol in package.json.

The XRP Ledger Foundation’s commitment to resolving the security issue underscores the ongoing efforts to safeguard the integrity of the XRPL ecosystem and protect users from potential threats.

Backdoor Compromised Developer Keys Kit Ledger Private Steal wallet XRP
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

North Korean Hackers Deploy Python-Based Trojan Targeting Crypto

June 20, 2025

XRP Price Falls 7% as Legal Expert Dismisses New Filing

June 19, 2025

Israeli Hacktivists Steal and Burn $90m+ from Iranian Crypo Biz

June 19, 2025

Legal Expert Reveals Why the SEC vs Ripple Case Should Still Be Relevant to XRP Investors

June 19, 2025
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Bitdeer Mined 196 Bitcoin Worth Over $21 Million In May

June 12, 2025

Crypto Fraud Penalties Propel SEC’s 2024 Enforcement to $8.2 Billion

November 27, 2024

Mantle, Securitize Unveil $400M MI4 Tokenized Crypto Index Fund

April 25, 2025
Price Chart


Explore insights on crypto, blockchain, taxes, and security. Stay informed with expert guides, tips, and the latest trends to navigate the digital asset world confidently


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Senate Passes Landmark Stablecoin Bill in Major Boon for Crypto Industry

June 20, 2025

Best New Crypto to Buy as Arizona Reconsiders Bitcoin Reserve Bill

June 20, 2025

Arizona revives bid for seized crypto reserve fund through House Bill 2324

June 20, 2025
Get Informed

Subscribe to Updates

Get the latest creative news From BuyCryptoNews directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2025 BuyCryptoNews - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.